OS Command Injection in AVideo - CVE-2026-33478
Published: May 4, 2026
AVideo
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to improper neutralization of special elements used in an os command in plugin/CloneSite/cloneClient.json.php when processing the videosDir value from a clone server response during clone operations. A remote attacker can supply a specially crafted videosDir value to execute arbitrary code.
Exploitation is possible as part of a chain in which clone secret keys are disclosed without authentication and used to obtain a database dump containing trivially crackable MD5 password hashes for administrative accounts.